OpenClaw Vulnerability Allows AI Log Poisoning via Unsanitized Headers

OpenClaw Vulnerability Allows AI Log Poisoning via Unsanitized Headers

First seen 18 Feb 2026, 18:23 UTC RedditEsecurityplanet 29.2

Article Content

Browse articles
ThreatCluster

OpenClaw versions prior to 2026.2.13 have a vulnerability that logs unsanitized WebSocket headers. This flaw creates a risk of AI log poisoning, potentially affecting systems that utilize these versions. Users are advised to update to the latest version to mitigate this risk.

Timeline

2026-02-17
Reddit post about log poisoning in OpenClaw
2026-02-18
Esecurityplanet article published detailing the vulnerability